Garden Finance disables app as Blockaid reports $450,000 exploit

cointelegraph2026-07-27 tarihinde yayınlandı2026-07-27 tarihinde güncellendi

Özet

Garden Finance has temporarily taken its app offline following an incident reported by Blockaid involving approximately $450,000. Blockaid stated an attacker drained funds from Garden's hash time-locked contracts (HTLCs) on multiple blockchains. However, Garden Finance clarified that its protocol and HTLC smart contracts were not compromised. The company attributed the loss to a breach of an independent solver's off-chain database, where fraudulent records caused the solver to release its own funds for unfunded swaps. Garden emphasized no user funds were lost or at risk, with the incident confined to solver-owned assets. The firm is working with security companies to trace and recover the funds and expects to restore services after completing security reviews. This follows a previous solver-related breach in October 2025.

[Updated July 27, 2026, 2:16 UTC: Revised to reflect clarifications from a Garden Finance spokesperson.]

Garden Finance said an independent solver’s off-chain database was compromised in an incident that prompted the cross-chain bridge and atomic swap protocol to temporarily take its app offline.

On Sunday, Blockaid said an attacker drained about $450,000 in USDT from Garden’s hash time-locked contracts (HTLC) on Ethereum, Base, Arbitrum and BNB Smart Chain. HTLCs are time-bound escrow contracts that Garden uses to facilitate atomic swaps between Bitcoin and assets on other networks. Blockaid described the exploit as ongoing and published addresses linked to the attacker and affected contracts.

However, a Garden Finance spokesperson told Cointelegraph that neither the protocol nor its HTLC smart contracts had been compromised. The company said the attacker breached the off-chain database of an independent solver and inserted fraudulent transaction records, causing the solver to release funds for swaps that had not been funded by the counterparty.

Garden said no user funds were lost or placed at risk and that the incident affected only solver-owned assets. The company is still confirming the total amount, assets and networks involved. It said services were paused as a precaution while the affected infrastructure was isolated and reviewed.

Blockaid acknowledged Cointelegraph’s request for comments.

Garden works with security firms to trace funds

Garden said it is working with zeroShadow, Quantstamp and Blockaid to trace and recover the funds. The protocol expects to restore services shortly, subject to completing security checks, but did not give a specific timeline.

“Garden’s protocol and HTLC smart contracts were not compromised, and no user funds were lost or at risk,” the company told Cointelegraph, adding that the incident was isolated to the off-chain infrastructure of one solver in its network of independent solvers.

The company also pointed to its recent SOC 2 Type II attestation as evidence of its investment in security and operational controls. Garden told Cointelegraph that its immediate priorities are securing the affected systems, tracing the solver’s funds and ensuring services resume only after the relevant reviews are completed.

Related: WEMIX says attacker moved about $724,000 after contract breach

The incident follows an October 2025 breach in which an attacker stole about $11.4 million after compromising the operating environment of one of Garden’s solvers. Garden said that incident also did not affect its protocol contracts or put user funds at risk.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

İlgili Sorular

QAccording to the article, what was the root cause of the $450,000 exploit affecting Garden Finance?

AThe root cause was the compromise of an independent solver's off-chain database. The attacker inserted fraudulent transaction records, which caused the solver to release funds for swaps that were not actually funded by the counterparty.

QDid the exploit compromise Garden Finance's core protocol or smart contracts, according to the company's statement?

ANo, according to Garden Finance's statement, neither the protocol nor its HTLC smart contracts were compromised. The incident was isolated to the off-chain infrastructure of a single independent solver.

QWhat action did Garden Finance take in response to the incident, and which security firms are they working with?

AGarden Finance temporarily took its app offline as a precaution. They are working with the security firms zeroShadow, Quantstamp, and Blockaid to trace and recover the stolen funds.

QWhat type of contracts were specifically targeted by the attacker, and on which networks?

AThe attacker targeted hash time-locked contracts (HTLCs) on the Ethereum, Base, Arbitrum, and BNB Smart Chain networks.

QHow does this recent incident relate to a previous security event involving Garden Finance mentioned in the article?

AThe article mentions a previous breach in October 2025 where an attacker stole about $11.4 million after compromising a solver's operating environment. Similar to the recent incident, Garden stated that the 2025 breach also did not affect its protocol contracts or user funds.

İlgili Okumalar

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru59 dk önce

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru59 dk önce

İşlemler

Spot
活动图片